Limits Related to Policies
Feature |
Metric |
Limit |
---|---|---|
Automatic policy discovery (formerly ADM) |
Maximum number of member workloads (endpoints) allowed for automatic policy discovery run on a single scope. |
10,000 |
Maximum number of conversations allowed for automatic policy discovery run on a single scope. |
10,000,000 |
|
Maximum number of member workloads (endpoints) allowed for automatic policy discovery on a branch of the scope tree. |
37,500 |
|
Maximum number of conversations allowed for automatic policy discovery on a branch of the scope tree. |
20,000,000 |
|
Maximum number of total unique workloads (endpoints) allowed for automatic policy discovery run. |
15,000,000 |
|
Maximum number of exclusion filters in Default Policy Discovery config. |
100 |
|
Maximum number of exclusion filters allowed per workspace. |
100 |
|
|
Maximum number of submissions allowed for Automatic Policy Discovery. |
5 |
Concrete policies |
Aggregate size of policies on agents installed on non-Kubernetes workloads. |
2.5 MB (About 2000 policies, depending on complexity) |
Aggregate size of policies on agents installed on Kubernetes nodes. |
7.5 MB (About 6000 policies, depending on complexity) |